PT-2012-5128 · Apache · Mod Pagespeed

Published

2012-09-15

·

Updated

2018-10-30

·

CVE-2012-4001

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions mod pagespeed versions prior to 0.10.22.6
Description The issue arises from the mod pagespeed module's failure to properly verify its host name, allowing remote attackers to trigger HTTP requests to arbitrary hosts. This can be demonstrated by requests to intranet servers.
Recommendations For versions prior to 0.10.22.6, update to version 0.10.22.6 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4001

Affected Products

Mod Pagespeed